All Apps and Add-ons

Modifying Permissions for Lookup Files viewed in the App

ktatis268
New Member

Is it possible to obfuscate lookups that users are do not have access to? I don't think it makes sense to display lookups and kv-stores that the users don't have access to edit. Also they're able to open them in the viewer which may be a bit of a security breach.

We would like our users to only see what they can edit.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Seeing only what you can edit is not very helpful, IMO. Users must have read access to the lookup files needed for their dashboards and reports. Without read access, users will see "lookup file not found" errors.

Only those few (typically admins) trusted to make changes to a lookup should have write access.

---
If this reply helps you, Karma would be appreciated.

dflodstrom
Builder

If you modify the permissions of the lookup and remove read access from that user's role then they will not be able to see it in the list of available lookups.

0 Karma

ktatis268
New Member

That suggestion is, unfortunately, a non-stater in our environment. We have multiple SHCs all of which have over 300+ lookup files... Most of these lookups are the ones that come baked-in with other apps/TAs.

There has to be a better way of obfuscating those files. The stanza below is not helping as I'd hoped.

[lookups]
access = read : [ ] , write : [ admin ]

0 Karma

dflodstrom
Builder

If you only want those with write access to have read access then it shouldn't be that difficult to add this to all of the apps with lookups you want to hide. I'm not suggesting doing this one-by-one by hand but manipulating the permissions with metadata seems to be how this is done.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...